Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Lightning AI

Lightning AI Vendor Cyber Rating & Cyber Score

lightning.ai

The AI development platform - From idea to AI, Lightning fast ⚡️. Code together. Prototype. Train on GPUs. Scale. Serve. From your browser - with zero setup. AI Studio is your laptop on the cloud. Zero setup. Always ready. Persistent storage and environments. Code on CPU. Debug on GPU. Scale to multi-node. Run sweeps, jobs and more. Scale models with PyTorch Lightning, Fabric, Lit-GPT, torchmetrics and more.


Lightning AI A.I CyberSecurity Scoring

Lightning AI
Company Information
Website:http://lightning.ai
Employees number:174
Number of followers:96,554
NAICS:5112
Industry Type:Software Development
Homepage:lightning.ai
Lightning AI Risk Score (AI oriented)
Between 650 and 699
logo
Lightning AISoftware Development
Updated:
30/04/2026
692/1000
Weak
B
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Lightning AI Global Score (TPRM)
xxxx
logo
Lightning AISoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Lightning AI
Lightning AIWeak
Current Score
692B (WEAK)
01000
1 incidents
-63 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
696Before Incident
JULY 2026
696Before Incident
JUNE 2026
695Before Incident
MAY 2026
755Before Incident
Breach
30 Apr 2026Lightning AI
PyTorch Lightning and Anthropic: PyTorch Lightning and Intercom-client Hit in Supply Chain Attacks to Steal Credentials

Malicious PyPI Versions of PyTorch Lightning Target Developers in Supply Chain Attack

692After Incident
CRITICAL-63
PYTANT1777580983
Malicious PyPI Versions of PyTorch Lightning Target Developers in Supply Chain Attack Threat actors compromised the popular Python package PyTorch Lightning, publishing two malicious versions 2.6.2 and 2.6.3 on April 30, 2026, as part of a broader software supply chain attack. The campaign, linked to the Mini Shai-Hulud incident that previously targeted SAP-related npm packages, was uncovered by security firms Aikido Security, OX Security, Socket, and StepSecurity. The compromised versions contained a hidden `_runtime` directory with an obfuscated JavaScript payload that executed automatically upon package import. The attack chain downloaded the Bun JavaScript runtime and deployed an 11MB obfuscated script (router_runtime.js) designed for credential theft. Validated GitHub tokens were used to inject worm-like payloads into up to 50 branches per repository, silently overwriting files with commits impersonating Anthropic’s Claude Code. Additionally, the malware modified local npm packages by adding a postinstall hook to package.json, incrementing version numbers, and repackaging tarballs. If published, these tampered packages would propagate the malware to downstream systems. The Python Package Index (PyPI) has since quarantined the affected versions. While the exact cause of the compromise remains under investigation, evidence suggests the PyTorch Lightning GitHub account was breached. Maintainers confirmed the malicious versions introduced credential-harvesting functionality and advised users to downgrade to version 2.6.1 and rotate exposed credentials. The attack has been attributed to TeamPCP, a threat group previously suspended from X for policy violations. The group has since launched a dark web onion site and claimed ties to LAPSUS$, while denying use of the VECT encryption tool instead asserting ownership of CipherForce, its proprietary ransomware locker. In a related incident, version 7.0.4 of the *intercom-client* npm package was also compromised under the Mini Shai-Hulud campaign, employing a preinstall hook to execute credential-stealing malware. Security researchers noted technical overlaps with prior TeamPCP attacks targeting Checkmarx, Bitwarden, Telnyx, LiteLLM, and Aqua Security Trivy.
INCIDENT DETAILS -
TYPE
Supply Chain Attack
MOTIVATION
Credential theft, malware propagation, supply chain compromise
IMPACT
Data Compromised: GitHub tokens, credentials, repository filesSystems Affected: Python and npm package ecosystems, downstream development environmentsOperational Impact: Unauthorized code commits, malware propagation, credential exposureBrand Reputation Impact: High (PyTorch Lightning, npm packages)Identity Theft Risk: High (credential harvesting)
DATA BREACH
Type Of Data Compromised: Credentials, GitHub tokens, repository filesSensitivity Of Data: High (authentication tokens, source code)Data Exfiltration: Yes (credential theft)File Types Exposed: JavaScript, npm package files, Python packages
APRIL 2026
755Before Incident
MARCH 2026
755Before Incident
FEBRUARY 2026
755Before Incident
JANUARY 2026
755Before Incident
DECEMBER 2025
755Before Incident
NOVEMBER 2025
755Before Incident
OCTOBER 2025
755Before Incident
SEPTEMBER 2025
755Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Lightning AI ?
?
What was Lightning AI's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Lightning AI's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Lightning AI's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Lightning AI's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Lightning AI's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Lightning AI's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Lightning AI's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Lightning AI's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Lightning AI's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Lightning AI's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Lightning AI's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on Lightning AI's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Lightning AI ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Lightning AI's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?